RandomQuery (Powershell)

First seen
2022-04-15 00:00:00
Malware type
rat, trojan
Family
Malware family
Profile updated
2026-07-07 14:39:16

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

A set of powershell scripts, using services like Google Docs and Dropbox as C2.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Ps1.Randomquery (report)
  • securonix.com — Securonix Threat Research Security Advisory New Deepgosu Attack Campaign (report)
  • securonix.com — Analyzing Deepdrive North Korean Threat Actors Observed Exploiting Trusted Platforms For Targeted Attacks (report)
  • s2w.inc — 920 (report)

External references